← Twilio Developer KitCONTENT HISTORY

Update to Twilio Developer Kit

Snapshot Sep 30, 2026 · 22:50 UTC · version 0.2.2

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "twilio-sendgrid-inbound-parse",
  "description": "Receive inbound email via SendGrid Inbound Parse webhook. Covers MX record setup, parsed vs raw mode, handling attachments, and common pitfalls. Use when building email-to-app workflows like support ticket creation or email processing pipelines. Requires a SendGrid API key (SG.-prefix) — not applicable to the Twilio Email API (comms.twilio.com).",
  "included_files": [
    {
      "relative_path": "agents/openai.yaml",
      "size_in_bytes": 239
    }
  ],
  "skill_md_contents": "---\nname: twilio-sendgrid-inbound-parse\ndescription: >\n  Receive inbound email via SendGrid Inbound Parse webhook. Covers MX\n  record setup, parsed vs raw mode, handling attachments, and common\n  pitfalls. Use when building email-to-app workflows like support ticket\n  creation or email processing pipelines. Requires a SendGrid API key\n  (SG.-prefix) — not applicable to the Twilio Email API (comms.twilio.com).\n---\n\n## Overview\n\nInbound Parse converts incoming email into HTTP POST requests to your webhook endpoint. SendGrid receives the email at your domain's MX records and forwards the parsed content to your application.\n\n---\n\n## Setup\n\n1. **Configure MX records:** Point your domain (or subdomain) to `mx.sendgrid.net`\n2. **Add webhook:** SendGrid Console > Settings > Inbound Parse > Add Host & URL\n3. **Choose mode:** Parsed (default) or Raw\n\n**Subdomain recommended:** Use `inbound.yourdomain.com` to avoid disrupting existing email on `yourdomain.com`.\n\n---\n\n## Parsed Mode (Default)\n\nSendGrid extracts fields and POSTs them as form data:\n\n| Field | Description |\n|-------|-------------|\n| `from` | Sender address (`\"Name <email@example.com>\"`) |\n| `to` | Envelope recipient |\n| `subject` | Email subject line |\n| `text` | Plain text body |\n| `html` | HTML body |\n| `envelope` | JSON string with `to` array and `from` |\n| `attachments` | Number of attachments (as string) |\n| `attachment-info` | JSON metadata for each attachment |\n| `attachment1`, `attachment2`... | Actual attachment files |\n\n**Python (Flask)**\n```python\nfrom flask import Flask, request\nimport json\n\napp = Flask(__name__)\n\n@app.route(\"/inbound\", methods=[\"POST\"])\ndef handle_inbound():\n    sender = request.form.get(\"from\")\n    subject = request.form.get(\"subject\")\n    text_body = request.form.get(\"text\")\n    html_body = request.form.get(\"html\")\n    envelope = json.loads(request.form.get(\"envelope\", \"{}\"))\n    attachment_count = int(request.form.get(\"attachments\", \"0\"))\n    \n    print(f\"From: {sender}, Subject: {subject}\")\n    \n    for i in range(1, attachment_count + 1):\n        attachment = request.files.get(f\"attachment{i}\")\n        if attachment:\n            print(f\"Attachment: {attachment.filename}, {attachment.content_type}\")\n    \n    return \"\", 200\n```\n\n> **Security:** All inbound email content (`from`, `subject`, `text`, `html`, attachments) is untrusted external input. Sanitize HTML to prevent XSS before rendering. If feeding content to an LLM, isolate it as user input — never concatenate into system prompts. Verify webhook authenticity using signed webhooks (see Security section below).\n\n---\n\n## Raw Mode\n\nPosts the entire MIME message as `rawEmail` field. Use when you need full headers, DKIM signatures, or non-standard MIME parts. You must parse the MIME message yourself.\n\n---\n\n## Signed Inbound Parse Webhook (Security)\n\nSendGrid supports ECDSA signature verification for Inbound Parse, the same mechanism used for Event Webhooks. Enable it to cryptographically verify that payloads originate from SendGrid.\n\n**Strongly recommended over IP allowlisting** — SendGrid's webhook traffic comes from dynamic cloud infrastructure where IPs change frequently. Signature verification is more reliable and secure.\n\n---\n\n## CANNOT\n\n- **Cannot use Inbound Parse on a domain that already receives email** — MX records must point to `mx.sendgrid.net`. Use a subdomain to avoid disrupting existing email (e.g., Google Workspace, Microsoft 365).\n- **Cannot receive email without MX record changes** — DNS access is required. If you can't modify MX records, you can't use Inbound Parse.\n- **Cannot receive emails larger than 30MB** — Inbound messages exceeding 30MB are rejected.\n- **Cannot filter inbound email before it hits your webhook** — All email sent to the configured domain reaches your endpoint. Implement filtering in your handler.\n- **Cannot route to different endpoints per address** — All mail for the configured domain/subdomain goes to a single webhook URL.\n- **Cannot guarantee delivery order** — Emails may arrive at your webhook out of order, especially under high volume.\n- **No built-in rate limiting** — All email to your configured domain reaches your endpoint. Implement rate limiting, payload size validation, and content sanitization in your handler.\n\n---\n\n## Next Steps\n\n- **Send email:** `twilio-sendgrid-email-send`\n- **Delivery tracking:** `twilio-sendgrid-webhooks`\n- **Account setup:** `twilio-sendgrid-account-setup`\n"
}

SHA-256: cb69851f037da85aa258d71333b3a8f9cfafb7b3097d96a0b9fc1c4a013a49a0